CVE-2018-1000098: Integer Overflow
Teluu PJSIP version 2.7.1 and earlier contains a Integer Overflow vulnerability in pjmedia SDP parsing that can result in Crash. This attack appear to be exploitable via Sending a specially crafted message. This vulnerability appears to have been fixed in 2.7.2.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2018-1000098?
The severity of CVE-2018-1000098 is high with a severity value of 7.5.
How can I exploit CVE-2018-1000098?
CVE-2018-1000098 can be exploited by sending a specially crafted message.
How do I fix the vulnerability CVE-2018-1000098?
The vulnerability CVE-2018-1000098 has been fixed in version 2.7.2 of Teluu PJSIP.
Which software versions are affected by CVE-2018-1000098?
Teluu PJSIP versions 2.7.1 and earlier are affected by CVE-2018-1000098.
Are there any references for CVE-2018-1000098?
Yes, you can find references for CVE-2018-1000098 at http://downloads.asterisk.org/pub/security/AST-2018-002.html, https://trac.pjsip.org/repos/ticket/2093, and https://security-tracker.debian.org/tracker/CVE-2018-1000098.